Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #deepseek-harness#dlp#dsh-plugin#secret-detection

dsh-dlp

数据防泄露:不可配置的工具门禁底线、工具结果脱敏与遥测脱敏(fail-closed)

charlotten7 @charlotten7 ⬇ 2 ★ 0 main

安装

dsh plugin --profile web add github:charlotten7/dsh-dlp
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

数据防泄露:不可配置的工具门禁底线、工具结果脱敏与遥测脱敏(fail-closed)

该插件未提供要点说明,请参考仓库 README。

deepseek-harnessdlpdsh-pluginsecret-detection
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/charlotten7/dsh-dlp
许可证MIT
主要语言main
下载量2
GitHub 星标0
最近推送2026-08-18
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# dsh-dlp

Data-loss prevention for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness),
built as an out-of-repo plugin.

📖 **[Full documentation](https://charlotten7.github.io/dsh-dlp/)**

## What it does

1. **Denies credential-file access and secrets bound for the network** — unconditionally, from
   `ctx.tools.guard()`, testing path-typed arguments against a table of credential stores and
   following symlinks first.
2. **Redacts secrets out of tool results** before the model reads them and before the session log
   records them, withholding a result it cannot clean.
3. **Redacts secrets out of exported telemetry**, closing a hole where `DSH_TELEMETRY_MODE=FULL`
   ships message text, tool arguments, results and workspace paths in the clear.
4. **Strips invisible characters that carry hidden instructions** — the Tags block, bidi
   overrides, runs of variation selectors — and strips terminal control sequences from the audit
   lane so a tool result cannot forge its own audit record.
5. **Neutralises remote markdown images in assistant output** and detects a tool call another
   plugin rewrote after the session log recorded it.
6. **Asks before the agent writes a file that changes future behaviour** — agent settings and
   hooks, `CLAUDE.md`, `.claude/rules/**` and the other agent rules directories, prompt
   templates, `.vscode/tasks.json`, `.mcp.json`, git hooks, CI workflows, shell startup files,
   `pnpm-workspace.yaml` — and before it writes a `*_BASE_URL` that would redirect a provider
   credential.
7. **Asks before a call switches off its own confirmation** — `non_interactive: true`,
   `approval_mode: auto`, an `apply` whose approval is still pending. Both `ask` tiers are
   prompts rather than controls: they live at `tools/pre-execute` and can be neutralised.
8. **Writes an audit record for every decision** — rule id, rule version, offsets, keyed hash.
   Never the secret, never the path or command that matched. `dsh-dlp report` reads it back.

## What this is not

**This is not a containment boundary.** The plugin runs in-process, at the agent's own uid.
Anything the agent can execute — a `bash` command, a `run_code` program, a mounted MCP server —
can read every file the guard denies and open its own sockets without the plugin seeing anything.
It closes the path where *the model* asks for credential material through a tool. It does not stop
code that is already running. If you need containment, that is the sandbox, `landlock-run`,
filesystem permissions and egress firewalling.

Three limits worth knowing before you rely on it:

- **Only the guard floor is unconditional.** Every other seam can be neutralised by a listener
  registered ahead of ours. `ctx.tools.guard()` is order-independent only because it has no allow
  arm.
- **The shell-command arm is advisory pattern-matching.** It catches an unobfuscated
  `cat ~/.ssh/id_rsa` and nothing that tries — one glob character, a `$(printf …)` reassembly or
  `python3 -c` all defeat it, each verified. **Do not count this arm as a control.**
- **Detection is pattern-based.** No entropy rule (measured, not assumed: at a false-positive-free
  threshold the miss rate is 100% below 22 characters). Encoded forms pass. A homoglyph defeats
  every rule in this package.

[The full list of limits →](https://charlotten7.github.io/dsh-dlp/)

## Install

A profile carrying only `@deepseek-ai/dsh-base` has no agent loop, so add a runnable bundle
alongside it or there is nothing for this plugin to guard:

```sh
dsh plugin --profile  add @deepseek-ai/dsh-headless@0.1.0-rc.6
dsh plugin --profile  add dsh-dlp
dsh --profile  --dump-config      # the dsh-dlp row should appear
```

Any harness from `0.1.0-rc.6` onwards in the `0.1.x` line works: the peer ranges accept it and CI
runs the end-to-end suite against every published rc in that range.

Pin `@deepseek-ai/dsh-headless` explicitly — its npm `latest` tag still points at `0.0.1-rc.1`.
The package ships a `cordis.patch.yml` bundle layer, so listing it in `dsh.profile.bundles` mounts
it with working defaults.

**Install from the registry or a packed tarball, not from a git spec:** `lib/` is a build output
git does not carry and no `prepare` script rebuilds it, so a git-spec row mounts and then fails to
load.

## Configure

```yaml
- id: dsh-dlp
  config:
    auditLog: /var/log/dsh-dlp.audit.jsonl
    redactionKeyFile: /var/lib/dsh/dsh-dlp.redaction-key
    policyFile: ./.dsh-dlp.yml        # optional, lowest trust
    breadthTier: true
    resultRedaction: true
    telemetryRedaction: true
    configWriteAsk: true
    approvalSuppressionAsk: true
```

`redactionKeyFile` is created on first mount with 32 random bytes at mode `0600`. Keep it out of
version control — it is what makes a placeholder's hash keyed rather than a bare digest anyone
holding a candidate secret could confirm.

**The guard floor has no configuration.** Credential-path denial and secret-argument denial are
security invariants, not deployment-varying tunables. A repo-local `policyFile` is the lowest
trust rank and may only *tighten*: add deny patterns, add egress tool names, raise a severity,
switch a pass on. Any downgrade makes the whole file invalid.

[Configuration reference →](https://charlotten7.github.io/dsh-dlp/configuration.html) ·
[What gets denied →](https://charlotten7.github.io/dsh-dlp/denials.html) ·
[Redaction and detection →](https://charlotten7.github.io/dsh-dlp/redaction.html)

## Reading the audit log

```sh
dsh-dlp report                       # everything in the audit sink
dsh-dlp report --since 24h
dsh-dlp report --kind guard-deny
```

Every record carries a rule id, rule version, span offsets and a keyed hash — never the matched
value.

[Audit record format →](https://charlotten7.github.io/dsh-dlp/audit.html)

## Mitigations for defects in the harness itself

Three registrations work around defects in DeepSeek Harness rather than in your configuration:
remote markdown images in assistant output, a tool call rewritten between `tools/pre-execute` and
the guard, and a telemetry redactor that cannot run under the shipped default. **None of them
closes its channel** and an upstream fix is better in all three cases.

[What each one does and does not close →](https://charlotten7.github.io/dsh-dlp/harness-mitigations.html)

## Development

```sh
nvm use 22           # Node ^22.19.0 || >=24, and pnpm 11
pnpm install
pnpm run typecheck
pnpm run test:coverage
pnpm run test:e2e    # boots a real dsh against a mock model; no API key
```

Coverage is gated at 100% per file: this is a security control, so an untested branch in a deny
path is an unproven deny path.

Design decisions and their rationale live in [ADR.md](ADR.md). Security policy is in
[SECURITY.md](SECURITY.md).

## License

MIT

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。